
GZDoom-Arbitrary-Code-Execution-via-ZScript-PoC
Proof of concept for CVE-2024-54756, a vulnerability I found in GZDoom's ZScript scripting engine.

Proof of concept for CVE-2024-54756, a vulnerability I found in GZDoom's ZScript scripting engine.

Android kernel exploit for CVE-2026-43499 (Futex-PI use-after-free) that gains temporary root on Xiaomi XIG04 to enable ADB. Includes automated…

Automated scanner and exploit for CVE-2025-34085, an unauthenticated RCE in the WordPress Simple File List plugin. Supports multi-target scanning,…

CVE-2026-48909 - Unauthenticated PHP Object Injection to RCE exploit for Joomla SP LMS extension versions <= 4.1.3. Exploits lmsOrders cookie…

Exploit generator for CVE-2017-11882, crafting malicious RTF documents that execute arbitrary commands or shellcode via the Equation Editor…

Proof-of-concept exploit for CVE-2025-52691: unauthenticated arbitrary file upload leading to RCE in SmarterMail. Includes vulnerability scanner,…

Demonstration exploit for CVE-2019-18276, a local privilege escalation vulnerability in Bash, using a crafted shared library to gain root access.

WordPress Medical Prescription Attachment Plugin for WooCommerce Plugin <= 1.2.3 is vulnerable to a high priority Arbitrary File Upload

POC for exploit of CVE-2011-1237

C-based exploit for CVE-2026-31431 in the Linux Kernel Crypto API, targeting aarch64 and amd64 architectures with shellcode generation and ancillary…

PoC of CVE-2021-4034 (PwnKit) for personal training purposes.

Proof-of-concept demonstrating remote code execution via prompt injection in GitHub Copilot Chat, using a crafted Python file to trigger a…

Exploit for CVE-2019-16278 targeting Nostromo Web Server 1.9.6, achieving remote code execution via directory traversal. Uses pwntools to deliver a…

Python exploit for CVE-2025-7340, an unauthenticated file upload vulnerability in the WordPress HT Contact Form widget, enabling remote code…

Proof-of-concept exploit for CVE-2022-22963, a Spring Cloud Function SpEL injection leading to remote code execution. Includes a shell script for…

Rejetto HFS (HTTP File Server) is a simple web file server that facilitates file sharing over a network or the internet.

Python-based proof-of-concept exploit for CVE-2023-4911 (Looney Tunables) targeting glibc dynamic loader's parse_tunables() for local privilege…

Write up exploit failed chain and experience tryin to sell your first nday